CVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

21 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 14:16

Updated : 2026-07-22 15:16


NVD link : CVE-2026-16447

Mitre link : CVE-2026-16447

CVE.ORG link : CVE-2026-16447


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type